3 ms·
Couldn't you just move from, say, using MD5(password) to bcrypt(MD5(password))? So when it becomes apparent that the old hash is no more secure, start using the
by pek 14y ago
Couldn't you just move from, say, using MD5(password) to bcrypt(MD5(password))? So when it becomes apparent that the old hash is no more secure, start using the combination of the old bad hash (MD5) and the new good hash (bcrypt). This way you can simply run once through the password database, hash each password hash there with the new better hash, and throw away the old hashes. No need to prolong the process until the users log in.
- EvilTerran 14y agoAs hashing functions aren't injective, composing them leads to a reduction of range (ie, a smaller set of possible output values). As such, (bcrypt . MD5) would almost certainly be a weaker hash than bcrypt alone. Might not be enough to make a difference, but I'd consult a cryptologist before betting on that.
- pek 14y agoYeah, it would be weaker against a collision attack. But that shouldn't be a concern as the purpose of the password hashing function is to protect against a preimage attack: finding the password given its hash. I can't see how the composition could be more vulnerable to a preimage attack than its parts. (Provided that the inner function's output is evenly distributed.)
- dsingleton 14y agoThey have some older APIs that depend on MD5(password) being used directly, to compare against auth credentials or to derive other hashes to verify API requests. Though older APIs they're still used by many older or infrequently updated clients, such as hardware devices with sold with Last.fm integration. Unfortunately, the longer you've been around the more likely you are to develop dependencies that make it more difficult to upgrade your password hashing. A new site can do whatever it wants with password hashing, but it becomes harder for older sites with more legacy dependencies to make that kind of change and Last.fm has been around for almost 10 years. This isn't to say "MD5 is cool, don't worry", but to try and illustrate some of the reasons behind this.